ASPICE · SUP.8 · The Enabling Layer

ASPICE SUP.8 Configuration Management

Not a sidecar process — the configuration-management data model that caps the maturity of every other process area. Outcomes, work products, and how they map to your tools.

In short

ASPICE SUP.8 Configuration Management establishes and maintains the integrity of all work products — identifying configuration items, controlling their versions and modifications, freezing baselines, and reporting status. It is the enabling layer: every other process area is a set of configuration items and links, so no process reaches CL2 beyond the maturity of the CM data model underneath it.

If you fix one process first, fix this one. SUP.8 is where the configuration-management data model lives — and that model is the basis that only allows mature processes across every other group.

Purpose & process outcomes

Purpose (per the ASPICE PAM): establish and maintain the integrity of all work products of a process or project and make them available to affected parties.

The process is achieved when these outcomes hold:

Base practices

SUP.8.BP1

Develop a configuration management strategy

Define what is under CM, the branching/baseline scheme, tools, and responsibilities.

SUP.8.BP2

Identify configuration items

Give every controlled work product a unique identity and characteristics per the strategy.

SUP.8.BP3

Establish a configuration management system

A system that stores items, versions, and links with controlled access.

SUP.8.BP4

Establish baselines

Freeze internally consistent sets of items at defined points (e.g. per release/milestone).

SUP.8.BP5

Control modifications and releases

Changes to items and releases go through defined control (ties to SUP.10).

SUP.8.BP6

Report configuration status

Record and report the status of items, baselines, and change requests.

SUP.8.BP7

Verify the information about configured items

Check completeness and consistency of the baselines and items.

Work products

The output work products SUP.8 asks for (named per the standard):

Map it to your tools

This is where the standard meets reality. Each work product and outcome has a concrete home — an issue type, work-item type, or model element — in the tools you already run. Types are configurable, so treat this as the typical ASPICE setup:

Work product / outcomeJiraPolarionCodebeamerDOORS NextEnterprise ArchitectConfluence
WP: Configuration management plan / strategyproject scheme + workflow config (documented)CM plan document / LiveDocCM plan document itemCM plan moduleCM plan page (branching/baseline scheme)
WP: Configuration item listsaved JQL filter defining the controlled setWork Item query / Collectiontracker view / saved querymodule object setmodel browser indexCI-list page
Outcome: item identity + version controlissue key + full change historyeach Work Item versioned (revisions)each tracker item versionedeach Object version-controlledeach element under version controleach page versioned
WP / outcome: baselineVersion / fix-version release snapshotBaseline (revision snapshot of a space)BaselineBaseline of a module / componentBaseline of a packagepage-version / space snapshot
Outcome: branch / variant controlrelease branches / components (weak)branched baselinesbranchingmodule variantsversion-controlled packages
Outcome: bidirectional traceability (suspect-aware)issue links + suspect (R4J / RTM)Linked Work Items + suspect flagtrace links + suspectlink modules«trace» relationships
WP: configuration status accountingJQL dashboards / reportsLiveReportsreports / dashboardsattributes + viewsmodel reportsstatus-accounting page
WP: backup / recovery & archive recordsinstance backup / admin recordsrepository backup recordsbackup recordsdatabase backup recordsmodel archivebackup/DR page

The trap isn't the tools — it's that the links between them are maintained by hand and decay the moment a requirement changes. (See best ASPICE tools.)

It only matures on one configuration-management data model

Here is the part almost everyone misses. SUP.8 can never reach a mature capability level (CL2+) on its own — it can only be as mature as the configuration-management data model underneath it. SUP.8 Configuration Management is the secret enabling layer: the shared data model of items, versions, baselines and links that is the basis on which every other process group becomes provable. Scatter that data model across a Jira project, a Polarion space, a DOORS module, an EA model and a Confluence tree, and the model is fragmented by construction — the traceability that SUP.8 depends on decays the moment anything changes, and no amount of process ceremony fixes it.

What actually unlocks maturity is a headless ALM — an API-first, tool-agnostic configuration-management data model that is the single source of truth for every work product and every link, readable and writable by both humans and agents — plus an agent/human workflow definition, coordination and traceability platform on top of it, so every change is planned, assigned (to a human or an agent), executed and traced against that one model. That is the layer that lets SUP.8 be mature instead of theatrical.

Where teams fail SUP.8

The maturity of every ASPICE process is capped by the maturity of the configuration-management data model underneath it. That's the whole game.The enabling-layer thesis

Every process area sits on the SUP.8 configuration-management data model.
Every process area sits on the SUP.8 configuration-management data model.

This is part of The Blueprint — our free template QMS

ASPICE deliberately gives you no blueprint. So we wrote one. This SUP.8 guide is part of The Blueprint — our free, open template QMS for ASPICE: every VDA-scope process area, its outcomes and work products, mapped to concrete artifacts in your tools and grounded in one configuration-management data model. Take it, use it, no cost.

Agents can only be trusted when the configuration items and baselines are themselves under control — which is exactly why the CM data model is the first thing to get right, and why it belongs in a headless ALM rather than five hand-synced tools. And we offer to implement The Blueprint for you: our agentic solutions (Vera generates SUP.8's work products and traceability as a byproduct of the build, each with a confidence score and audit trail) running on a partner headless ALM — the API-first configuration-management data model that makes the whole thing provable.

Frequently asked questions

What is SUP.8 in ASPICE?

SUP.8 Configuration Management is the process that establishes and maintains the integrity of all work products — identifying configuration items, controlling versions and modifications, establishing baselines, and reporting status. It is the enabling layer the rest of ASPICE depends on.

Why is configuration management the enabling layer?

Because every ASPICE work product is a configuration item with a version and links, and no process can be more mature than the CM data model beneath it. Weak CM caps the capability level of SYS, SWE, SUP and MAN alike.

What are the SUP.8 work products?

A configuration management plan/strategy, a configuration item list, baselines, configuration status/status-accounting records, and backup/recovery records.

How does SUP.8 map to Jira or Polarion?

In Polarion every Work Item is a versioned configuration item and a Baseline freezes a consistent revision; in Jira issues carry keys and history with fix-versions/releases as baselines and issue links (with suspect flags) as traceability. Both need the links kept consistent as items change — which is where a headless ALM helps.

Part of the ASPICE explainer series

Grounded in the standard, honest about the theater: All VDA-scope process areas · CM data model & headless ALM · SUP.10 Change Requests · SWE.1

Get The Blueprint. Have us implement it.

The Blueprint is our free template QMS for ASPICE. We implement it with our agentic solutions on a partner headless ALM — SUP.8's work products and traceability generated in your tools, with a confidence score and audit trail on every artifact.or book a compliance teardown →

See Vera →